Cleartext storage of sensitive information in Fujitsu products - CVE-2023-39903
Published: September 14, 2023
Vulnerability identifier: #VU80784
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N]
CVE-ID: CVE-2023-39903
CWE-ID: CWE-312
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to cleartext storage of sensitive information in the ismsnap component. A local user can retrieve the password for the proxy server that is configured in ISM.
Affected software
Infrastructure Manager Advanced Edition
Infrastructure Manager Advanced Edition for PRIMEFLEX
Infrastructure Manager Essential Edition
Infrastructure Manager Advanced Edition for PRIMEFLEX
Infrastructure Manager Essential Edition
How to mitigate CVE-2023-39903
Install updates from vendor's website.
Infrastructure Manager Advanced Edition - update to 2.8.0.061
Infrastructure Manager Advanced Edition for PRIMEFLEX - update to 2.8.0.061
Infrastructure Manager Essential Edition - update to 2.8.0.061
Infrastructure Manager Advanced Edition for PRIMEFLEX - update to 2.8.0.061
Infrastructure Manager Essential Edition - update to 2.8.0.061